What is CVE-2026-25253?
CVE-2026-25253 relates to a critical vulnerability exploited by a Chinese threat actor during infrastructure migration, targeting AI-API resellers like derouter.ai and exposing 775 upstream API keys. The campaign utilizes advanced tooling including Hermes and SliverC2, necessitating immediate IOC-based network monitoring and revocation of compromised credentials.
Azərbaycanca: CVE-2026-25253 çinli təhdid aktyorunun yeni serverə miqrasiyası zamanı aşkarlanan kritik bir zəiflik və ya ekspluatasiya kampaniyası ilə bağlıdır. Bu fəaliyyət AI əsaslı hədəflərə, o cümlədən derouter.ai kimi API resellerlərinə təsir edərək 775 API açarının ifşasına səbəb olub. Müdafiə üçün təqdim olunan İOC-lər əsasında şəbəkə monitorinqini gücləndirmək və təsirlənmiş API açarlarını dərhal ləğv etmək tövsiyə olunur.
Related CVEs
link basis: shared vendors: Claude, GPT
FAQ2
Which threat actor is associated with CVE-2026-25253 and what type of target does it affect?
CVE-2026-25253 is attributed to a Chinese threat actor and involves an exploitation campaign targeting AI-API resellers such as derouter.ai.
What key mitigation steps are recommended for CVE-2026-25253?
It is recommended to strengthen network monitoring based on the provided IOCs and immediately revoke the 775 compromised API keys.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.